TL;DR
Get monitors, keyboards and dev gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
The unofficial Rust and Python tapo library added support for TP-Link’s TPAP protocol in v0.11.1, released on Oct. 4, 2025, according to its maintainer. Compatible lights, plugs, power strips, hubs and some cameras can now connect with the Tapo app’s Third-Party Compatibility setting off; some camera models and hubs still use other protocols or require the setting to be on.
The unofficial tapo Rust and Python library added support for TP-Link’s TPAP protocol in version 0.11.1, released Oct. 4, 2025, according to the project maintainer. The change lets compatible Tapo lights, plugs, power strips, hubs and some cameras connect while the app’s Third-Party Compatibility setting is off, a setting that previously blocked the library from communicating with devices using TPAP.
The maintainer says the library now detects which protocol a device uses and logs in accordingly. Users can connect by IP address or use the library’s device-discovery feature without changing their client code. The update applies to both language versions: the Python package is a wrapper around the Rust crate, and both share the same version number. The maintainer says the release supports TPAP on devices whose firmware requires it, while other models continue to use protocols they already support.
The release has limitations. An H200 camera hub running firmware 1.7.5 still announces AES SSL whether Third-Party Compatibility is on or off, and the library uses that protocol. Camera support depends on model and firmware: the report says C220 and C510W cameras on firmware 1.3.4 use TPAP, while a C210 on firmware 1.5.2 does not. That C210 still requires Third-Party Compatibility to be on because it rejects the library’s AES SSL login when the setting is off.
The maintainer also warns that repeated incorrect passwords can trigger a temporary device lockout. The library reports invalid credentials as TPAP_CREDENTIALS and an authentication-attempt limit as TPAP_AUTH_ATTEMPTS_LIMIT; users should not repeatedly retry those errors. The protocol work was part of a sequence of three releases: v0.10.0 on Sept. 28, v0.11.0 on Oct. 2 and v0.11.1 on Oct. 4, 2025. The maintainer says the releases also added a device family and two requested app features, but the supplied report does not detail those additions.
Local Access Without the Compatibility Switch
The update matters to people who manage Tapo devices through third-party software, including local automation setups. Before TPAP support, the maintainer says, devices that had moved to TPAP were unreachable through this library unless owners enabled Third-Party Compatibility. The new protocol support gives compatible devices another way to accept the library’s connection while that setting remains off.
That is a practical change, not a guarantee that every device now works with the setting disabled. The maintainer describes exceptions by model, firmware and device type, and says some cameras still rely on older behavior. Owners should check the protocol and firmware behavior for their particular device rather than assume the release removes every compatibility barrier.
The setting also carries a security trade-off. TP-Link’s FAQ, as quoted in the maintainer’s report, says Third-Party Compatibility is disabled by default “to ensure security” and that turning it on “may reduce the security of your devices.” TPAP support can reduce the need for that setting on supported devices, but the report does not provide an independent security audit or comparative technical measurements establishing how much safer TPAP is.
As an affiliate, we earn on qualifying purchases.
From KLAP to TPAP on Tapo Devices
The protocol change follows earlier transitions in how Tapo devices communicate with third-party clients. The maintainer reports that firmware updates in 2023 moved lights and plugs from an older AES protocol to KLAP, requiring client developers to add support. In late 2024, TP-Link introduced Third-Party Compatibility as a setting that could restore older local login behavior for some devices.
According to the report, plugs began receiving firmware 1.4.0 with TPAP in October 2025, and lights followed on firmware 1.4.1 to 1.4.3 in the first half of 2026. With the setting off, affected devices use TPAP; with it on, they use KLAP. The report says cameras differ: they have used AES SSL, and support for TPAP varies across models and firmware. The library’s v0.11.1 update addresses the new protocol while retaining AES SSL for camera-related devices.
The maintainer says v0.11.0 removed a separate, older AES protocol that had been retained for lights and plugs. The report distinguishes that protocol from AES SSL: although related in the kind of encrypted envelope used, AES SSL operates over HTTPS and has a different login. The library continues to support AES SSL where devices require it.
““It is disabled by default to ensure security.””
— TP-Link FAQ, as quoted in the maintainer’s report
As an affiliate, we earn on qualifying purchases.
Device Support Still Varies
The report does not give a complete list of supported device models and firmware versions, nor does it identify every camera that can use TPAP. It gives examples, but says camera compatibility varies. Users may need to test their exact model and firmware, and the report does not say whether TP-Link plans to extend TPAP across all Tapo devices.
The technical security comparison also remains limited in the supplied material. The maintainer says TPAP is safer than KLAP, but the provided text ends before explaining the supporting mechanism or evidence. No independent assessment is cited here, so the security comparison should be treated as the maintainer’s claim rather than an independently established finding.
It is also unclear whether future firmware updates will change protocol behavior or introduce further exceptions. TPAP itself was not documented by TP-Link, according to the maintainer, and TP-Link’s position on continued compatibility with unofficial clients is not specified beyond the quoted statement that Home Assistant is not an officially supported platform.
TP-Link Tapo camera firmware update
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Check Firmware and Library Releases
Users can update to tapo v0.11.1 and check whether their device and firmware support TPAP with Third-Party Compatibility off. The maintainer says existing client code should work without changes, whether devices are reached by IP address or discovery. Users should avoid repeated retries after credential or authentication-limit errors, as the device may temporarily refuse logins.
For developers and device owners, the next useful developments would be a fuller compatibility list and details about protocol behavior across additional firmware versions. The source report does not announce a specific future release date or a TP-Link update, so further support and any changes to device firmware remain unconfirmed.
third-party Tapo device controller
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What changed in tapo v0.11.1?
It added support for TPAP, allowing the library to connect to compatible Tapo devices that use that protocol. The maintainer says the release covers both Rust and Python versions.
Do users need to change their code?
The maintainer says no code changes are needed. The library detects the protocol used by a device and works through either direct IP connections or device discovery, where supported.
Can every Tapo camera now work with Third-Party Compatibility off?
No. Support varies by model and firmware. The report says C220 and C510W cameras on firmware 1.3.4 use TPAP, while a C210 on firmware 1.5.2 still requires Third-Party Compatibility to be on.
What happens after too many incorrect passwords?
A TPAP device may temporarily refuse logins after repeated failures. The library reports incorrect credentials as TPAP_CREDENTIALS and an authentication-attempt limit as TPAP_AUTH_ATTEMPTS_LIMIT; the maintainer advises against retrying either error in a loop.
Is TPAP officially documented or endorsed by TP-Link?
The maintainer’s report says TPAP was not documented by TP-Link and describes the library as unofficial. It quotes TP-Link saying Home Assistant is not an officially supported third-party platform; the supplied material does not establish a broader endorsement of the library.
Source: hn
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
